deepseek-harness
deepseek-ai
DeepSeek Harness: Everything is a Plugin.
PROJECT TOPICS
PROJECT README
Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts sensitive material (API keys, tokens, credentials) from what the model sees:
agent/pre-step): user messages are rewritten to redacted copies
before they enter the session log and the model request. Already-logged tool
results are redacted through session surface replacement, preserving the
original append-origin events in the durable log.llm/stream): text, reasoning, and tool-call argument deltas are
redacted before the agent loop logs them, so the log and future model context
stay consistent. block-end payloads are also redacted so the assembled
assistant message cannot reintroduce a secret.Add the row to a Cordis patch:
- insert:
- id: dsh-model-redactor
name: dsh-model-redactor
config:
enabled: true
The package ships cordis.patch.yml and declares dsh.bundle.patch for bundle
profiles.
| Field | Type | Default | Description |
|---|---|---|---|
enabled |
boolean |
true |
Master switch. |
replacement |
string |
[REDACTED] |
Replacement text (1..128 chars). Must not itself match a built-in secret pattern. |
customRegexes |
Array<{ pattern, flags?, replacement? }> |
[] |
Extra regex rules. |
customWords |
Array<string \| { word, replacement? }> |
[] |
Exact-word rules. |
Built-in rules are fixed and cannot be disabled. They cover OpenAI-style sk-,
Bearer, Basic, GitHub tokens, Slack tokens, JWTs, assignment patterns,
PEM private-key blocks, and AWS AKIA access key IDs.
pnpm build
pnpm test
tsc emits lib/. Unit and integration tests use Vitest.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: 无有效分类标签。